The long tail of Clop’s PTC hack is just beginning to emerge
ID: 0a4c6a14-bd78-556e-a7c6-141036843e96
STIX ID: report--0a4c6a14-bd78-556e-a7c6-141036843e96
Feed Name: CyberScoop
Threat Score
Clop exploited a critical zero-day (CVE-2026-12569) in PTC Windchill and FlexPLM to conduct a large-scale extortion campaign: the group deployed a custom Windchill web shell and toolkit to decrypt credentials, move laterally, exfiltrate data from dozens of organizations (including major enterprises), and send extortion demands while vendors and agencies published patches and indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
